Cyber Incident Response Analyst with OT/ICS/SCADA / Travel & Active TS
$104k - $166kPeraton Corporation
ResponsibilitiesPeraton is currently seeking to hire an experienced Incident Response Analyst (ICS/OT/SCADA) for its' Federal Strategic Cyber group. Location: On‑site in Arlington, VATravel: Approximately 40%Peraton is seeking an experienced Incident Response Analyst with strong OT/ICS/SCADA expertise to support its Federal Strategic Cyber program. This role involves responding to cyber incidents across critical infrastructure sectors and working closely with technical teams, forensic analysts, and mission partners to safeguard national‑level systems.In This Role, You Will: Respond to cybersecurity incidents across ICS, OT, and IT environments and provide recommendations to prevent recurrence within critical infrastructure sectors.Apply functional knowledge to resolve incidents, conduct proactive threat hunts, and contribute to solutions for problems of moderate scope and complexity.Support highly technical operations and forensic analysis while advising client decision‑makers.Provide sector‑specific expertise for one or more critical infrastructure areas, including Water, Power, Critical Manufacturing, and Transportation.Follow established procedures for incident response and escalation.Help define and refine response procedures for industrial control system environments.Apply traditional incident response and threat‑hunting tradecraft to ICS/critical‑infrastructure environments while accounting for operational constraints.Collaborate with host, network, and cloud forensic analysts to meet mission requirements for incident response and threat‑hunting engagements.Maintain accurate documentation of incident response activities and findings.Prepare and deliver incident reports to management and stakeholders.Work effectively in a team environment and contribute to mission success.Stay current on cybersecurity trends to enhance hunt and response operations.Demonstrate strong attention to detail, critical thinking, and customer‑service orientation.Self‑teach and test new tools, methodologies, and techniques as needed.Meet on‑site requirements of at least one day per week (up to three days depending on mission needs).Travel up to 40%.QualificationsRequired Qualifications:Bachelor’s degree and 5 years of relevant experience; Master’s degree and 3 years. An additional 4 years of relevant experience will be considered in lieu of a degree.Must have 1–2 years of relevant Threat Hunting or DFIR experience directly supporting Critical Infrastructure (CI) / ICS environments.Experience conducting security site assessments, including analysis of network security architecture, baseline ports/protocols/services, and asset characterization.Experience using SIEM tools for pattern identification, anomaly detection, and trend analysis.Experience analyzing ICS network protocols such as ModBus, ENIP/CIP, BACnet, DNP3, etc.Experience with common open‑source and commercial tools used in event analysis, incident response, forensics, malware analysis, or security operations.Experience with host‑based and network‑based collection and detection tools (OSS/COTS).U.S. citizenship required. Active Top Secret security clearance.Ability to obtain a TS/SCI for continued employment.Ability to obtain and maintain a favorably adjudicated DHS background investigation.Desired Qualifications:Certifications such as GISCP, GCFA, GNFA, GRID, or OT sensor certifications.2+ years of Threat Hunting or DFIR experience.Experience on DoD Cyber Protection Teams.Experience performing digital forensics on laptops/desktops, PLCs, HMIs, Historians, and SCADA systems.Experience with SIEM platforms (e.g., Splunk) including threat hunting, analytic development, dashboards, and reporting.Familiarity with critical‑infrastructure frameworks (NIST, IEC 62443).Ability to automate repeatable tasks.Scripting experience in Python, Bash, PowerShell, and/or JavaScript.Peraton OverviewPeraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.Target Salary Range$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.EEOEEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.Job SummaryRequisition ID: 2026-163351Position Category: Intel and Threat AnalysisClearance: Top Secret/SCI
$100k - $125k
...solutions provider is seeking an Incident Response Expert III in Arlington, VA.... ...analytical skills and an active TS/SCI clearance. Candidates... ...of experience in the field, with expertise in network security... ...national security missions. #J-18808-Ljbffr Argo Cyber SystemsCyber$160k - $210k
Armis, the cyber exposure management & security... ...States (Remote with Travel) Clearance Requirement Active DoD TS/SCI Clearance - With... ...Intelligence Community (IC)/DoD with an active... ...formal technical responses to queries and RFPs... ..., DISA STIGs, etc. OT/ICS experience...TravelCyberLocal areaRemote work$86k - $138k
...Control System Cyber Threat Intelligence Analyst for its... ...technology (OT) and industrial... ...control system (ICS) environments... ...exposed ICS/SCADA assets, assess... ...or malicious activity.Fuse multiple... ...forward-deployed incident response and threat... ....Familiarity with ICS/SCADA...CyberContract workCurrently hiringShift work- ...Alliance seeks a Cybersecurity Risk Analyst to support enterprise cyber defense in the Washington, D.C.... ...operational risks and process gaps, support incident-response, and translate complex cyber... ..., VA and the candidate must hold TS/SCI with CI Poly. #J-18808-Ljbffr Ops Tech...Cyber
- ...threat analysis, and response to cyber incident reports. Experience with industrial Control Systems (ICS), Operational technology (OT), Supervisory... ...Acquisition (SCADA) systems, and the... ...citizenship required. An Active Top Secret... ...cloud forensic analysts to meet the...CyberCurrently hiring
$111k - $122k
...of our company. With offices all... ...Computer Security Incident Response AnalystThis is... ...Incident Response Analyst for our... ...and investigate cyber security events... ...signs of malicious activity in a Security Information... ...local travel to customer sites... ...requires a USA TS/SCI with...TravelCyberFull timeWork experience placementLocal area- ...leading cybersecurity firm is seeking a Cloud Forensics Analyst to support onsite incident response to cyber-attacks. The role involves acquiring and analyzing... ...experience in cyber forensics and hold an active TS/SCI clearance. The position offers substantial training...Cyber
$164.38k - $189.75k
...related mission activities remain... ...interference. Responsibilities include:... ...risks associated with critical systems... ...Clearance: Active TS/SCI w/ polygraph... ...Intelligence Community (IC). GDIT IS... ...Hours: 40 Travel Required: Less... ...AI/ML, Cloud, Cyber and application...TravelCyberTemporary workImmediate startRemote workWorldwideFlexible hours- ...IR) specialist with specific skills... ...holiday workdays. Responsibilities Provide on-site... ...of CSSP/IR incidents including implementing... .... Conducting active hunting for... ...Qualifications Current TS security... ...adjust focus. Travel There is no travel... ...RESPONSE ANALYST #J-18808-Ljbffr...TravelCyberWork at officeMonday to FridayWeekend work
- ...is seeking Host Forensics Analysts to support the DHS’s Hunt and Incident Response Team (HIRT). This role focuses... ...response, requiring an active TS/SCI clearance. Candidates should... ...8 years of experience in cyber forensic investigations, with specific knowledge of...Cyber
$100k - $125k
Incident Response Expert III (Cyber Eviction Analysts) Location: Washington DC Metro Area (On-Site) Citizenship... ...: US only Clearance: Active TS/SCI (DHS EOD Suitability... ...technical precision with operational agility—... ...expertise Must be able to travel domestically on short...TravelCyberLocal areaImmediate start- Responsibilities:- Perform Computer Security Incident Response activities for a large global enterprise, coordinate with other enterprise IT teams to record and report... ...and assist security analysts in building operational... ...the full range of IT cyber security tasks.- Strong...CyberWork experience placement
- ...focus has been delivering cyber solutions to effectively manage... ...! TDI is seeking a Senior Incident Response Analyst to join our team in support... ..._ This position is hybrid with commute to the Arlington,... ...coordinate cyber incident response activities across the full Incident...CyberPermanent employment
- ...Job Description Incident Response Expert / Cyber Eviction Analyst Location: Arlington... ...VA Must have an active Top Secret Security... ...services with next-generation technology... ...citizen with an active TS/SCI clearance and... ...suitability ~ Ability to travel domestically on...TravelCyber
- ...trusted partnership with our government... ...is looking for a Cyber Eviction Analyst to support on‑site incident response to civilian Government... ...incident response activities Serves as... ...Must be able to travel domestically on short... ...requires an Active TS/SCI clearance and...TravelCyberImmediate start
$131.3k - $237.35k
...has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program.The... ..., mitigate, and respond to cyber threats and adversarial activity on the DHS Enterprise. The DHS SOC... ...and scope of Incidents• Expertise with Cyber Kill Chain and have utilized...CyberFull timeFlexible hours$105.2k - $196.5k
...Services brings together cyber and IT security to... ...federal agencies with the most... ...security. You are ICS/OT Architect dedicated... ...vulnerabilities, threat activity, and industrial... ...protocols, and SCADA/PLC/HMI platforms... ...threat hunting, or incident response in OT environments...CyberLive inWork at officeLocal area- ...Athene is searching for a Tier 2 Incident Response Analyst (IR) to support a law... ...and investigating potential cyber threats. As a SOC team member... ...for evidence of adversarial activity Perform in-depth analysis and... ..., and impact Collaborate with cyber threat hunting and cyber...CyberPart timeShift workNight shiftWeekend workDay shift2 days per week
$96.57k - $130.65k
...innovation.As a Data Analyst supporting CIS,... ...critical IT services.Key responsibilities include:Collect,... ...:Clearance: Active TS/SCI clearance a favorable... ...with Service CentralHands... ...illness and business travel and accident insurance... ...capabilities in AI, cloud, cyber and software...TravelCyberTemporary workImmediate startWorldwideFlexible hours- Armis, the cyber exposure management & security company, seeks a Senior Sales Engineer (IC/DoD) with an active TS/SCI clearance for remote work with regular travel across the DC metro and federal sites. This role requires hands-on experience in networking and cybersecurity...TravelCyberRemote job
- ...specialized assets and collaborates with law enforcement and foreign... ...Friday.Required Clearance: Active TS/SCISenior Legislative and... ...threat finance efforts. Key Responsibilities:Analyze congressional... ...Active TS/SCI Citizenship: US Travel: based on government needsTravelFor contractorsWork at officeRemote workMonday to FridayFlexible hours
$131.3k - $237.35k
...has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program.... ...analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS Enterprise. The DHS SOC... ...and scope of Incidents Expertise with Cyber Kill Chain and have...CyberFlexible hours$53.9k - $120.1k
Cybersecurity Incident Response Triage IR Analyst Arlington, VA The Cybersecurity Incident... ...presence. The Work Actively monitor and respond to cybersecurity... ...and scope Coordinate with the lead and other... ...response lifecycles, common cyber-attacks, insider-threat indicators...CyberWork experience placementLive inWork at officeLocal area- ...Information System Security Analyst to join our IT team in... ...sensitive data and systems from cyber threats, monitoring activity, identifying... ...proactive mindset to stay current with IT security trends. You will work on incident response, risk assessments, policy development...Cyber
$132.48k - $336.96k
...Responsibilities About the Team The TikTok USDS JV... ...enterprise-wide incidents, including post-incident... ...-the-sun model with our global SOC... ...incidents. As an IR Analyst, you will belong... ...and/or malicious activity occurring within... ...the Hunt team, Cyber Threat Intelligence...CyberTemporary workShift work- ...Inc. is seeking a Senior Analyst-CBRN in Washington, DC, to... ...the Office of WMD Response and Planning. This position... ...capabilities against CBRN incidents. Applicants must have an active Top-Secret clearance, a minimum... ...role requires up to 25% travel and supports the U.S....TravelWork at office
$102.5k - $188.9k
...Our Deloitte Cyber team understands... ...clients to operate with resilience,... ...to exploitation activity before it disrupts... ...Exploitation Analyst, you will... ...investigating incidents, assessing vulnerabilities... ..., incident response, exploit... ...EDR)Ability to travel up to 20%, on average...TravelCyberWork at office- ...specialized assets and collaborates with law enforcement and foreign... ...Friday.Required Clearance: Active TS/SCISenior Performance and... ...Performance Metrics Analyst is responsible for designing, monitoring, and... ...Active TS/SCI Citizenship: US Travel: based on government needsTravelFor contractorsWork at officeRemote workMonday to FridayFlexible hours
- Incident Response Engineer-JourneymanIntermittent Telework: Arlington, VATS/SCI... ...security alerts, leads triage activities, and coordinates containment and recovery actions with operations, IT, and mission... ...potential regulatory needs.Active TS/SCI security clearance U.S....Remote work
- Position Summary The Incident Responder provides hands-on cyber incident response across Critical... ...operations, collaborating with hunt and... ...response, including travel as needed. Conduct... ...identify attacker activity, persistence... ...Experience with ICS/OT or critical infrastructure...TravelCyberLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Incident Response Analyst with OT/ICS/SCADA / Travel & Active TS. Be the first to apply!
- information security consultant Arlington, VA
- cyber security analyst Arlington, VA
- remote cyber security analyst Arlington, VA
- cyber forensics Arlington, VA
- cyber sales Arlington, VA
- cyber threat intelligence analyst Arlington, VA
- cyber Arlington, VA
- travel full time Arlington, VA
- travel registered nurse rn Arlington, VA
- traveling retail merchandising Arlington, VA


